| MD5 | e33744bc5cb053bb42ec76ba96456d0a |
| SHA1 | 3839ebe2b860635d2a0d5e5a7175c8c7b558f9c5 |
| Filename | BP_VVIP.exe |
| IPs | [180.70.134.239] |
| IPs | [93.188.134.136] |
| IPs | [125.141.132.106] |
| IPs | [93.188.134.149] |
| IPs | [93.188.134.202] |
| IPs | [93.188.134.152] |
| IPs | [93.188.134.207] |
| IPs | [93.188.134.135] |
| Domains | [updatesii.tistory.com] [cfile23.uf.tistory.com] [pds26.egloos.com] |
| IP Addresses | [180.70.134.239] [93.188.134.136] [125.141.132.106] [93.188.134.149] [93.188.134.202] [93.188.134.152] [93.188.134.207] [93.188.134.135] |
| Antivirus | [Backdoor.Win32.Blohi] |
| [Backdoor:Win32/Blohi.B] | |
| [BKDR_BLOHI.SM] | |
| [Dropped:Generic.Malware.SLYBdb.721A9F3F] | |
| [Mal/VBCheMan-A] | |
| [Malware.QVM06.Gen] | |
| [ObfuscatedAOT!hb!B1396256EA50] | |
| [PE:Backdoor.Blohi!6.31D] |